CVE-2022-40687 - Breaking Down the CSRF Flaw in Creative Mail Plugin <= 1.5.4 for WordPress
---
Introduction
On September 27, 2022, a security flaw was reported as CVE-2022-40687—marking a significant vulnerability in the Creative Mail plugin for WordPress
CVE-2022-43308 - How Attackers Can Create Admin Accounts on Intelbras SG 2404 MR Switches
In late 2022, a serious vulnerability was discovered in the INTELBRAS SG 2404 MR managed network switch, specifically in firmware version 20180928-rel64938. This vulnerability,
CVE-2022-36784 - Remote Code Execution in Elsight Halo’s WiFi Ping API Endpoint
CVE-2022-36784 is a critical remote code execution (RCE) vulnerability affecting the Elsight Halo device—a popular product for secure data communication over cellular
CVE-2022-43506 In Delta Electronics DIAEnergie v1.9.02.001, SQL Injection can be done via Network.
communication. This can be leveraged to control the functionality of the device and obtain sensitive information. Delta Electronics DIAEnergie version 1.9.02.001 and
CVE-2022-43452 In Delta Electronics DIAEnergie versions before v1.9.02.001, SQL Injection can be
injected.
request when DIAEnergie is configured to expose an external database. DIAEnergie versions prior to v1.9.02.001 allows an attacker to inject SQL queries
Episode
00:00:00
00:00:00